# Import logs using filebeat for a java app running on kubernetes

**URL:** https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625
**Category:** Beats
**Tags:** filebeat
**Created:** [April 19, 2021, 8:37pm UTC](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625 "2021-04-19T20:37:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)
#### Post date: [April 19, 2021, 8:37pm UTC](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625/1 "2021-04-19T20:37:48Z")

</div>

Hello

I am reading the documentation of now to format and read logs on a Java app that is running in kubernetes [here](https://www.elastic.co/guide/en/ecs-logging/java/1.x/setup.html). In this documentation said to enable hint based discovery and add the annotation that are using the logs using ECS loggers. Where exactly I need to add those annotatations since I have added in my Deployments under metadata and did not do anything and then moved them under the templates/metadata and I get the following error when I try to apply the changes: `error: error validating "file.yaml": error validating data: ValidationError(Deployment.spec.template.metadata.labels.annotations): invalid type for io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta.labels: got "map", expected "string"; if you choose to ignore these errors, turn validation off with --validate=false`

The template section look like this:

```auto
...
  template:
    metadata:
      labels:
        app: front
        tier: frontend
        type: webapp
        annotations:
          co.elastic.logs/json.keys_under_root: true
          co.elastic.logs/json.overwrite_keys: true
          co.elastic.logs/json.add_error_key: true
          co.elastic.logs/json.expand_keys: true
    spec:
      securityContext:
        runAsUser: 100
        runAsGroup: 101
        fsGroup: 100    
      containers:
        - name: front
          image: image:tag
          env:
          - name: POD_NAME
            valueFrom:
              fieldRef:
                fieldPath: metadata.name
          - name: NAMESPACE
            valueFrom:
              fieldRef:
                fieldPath: metadata.namespace
...

```

Thanks for you help in advance.

---

<div class="post-metadata">

### Author: ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)
#### Post date: [April 19, 2021, 9:11pm UTC](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625/2 "2021-04-19T21:11:07Z")

</div>

Figured it out. The `annotations` has to be on the same level with `labels` and the `true` in quotes since it has to be string.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 17, 2021, 11:12pm UTC](https://discuss.elastic.co/t/import-logs-using-filebeat-for-a-java-app-running-on-kubernetes/270625/3 "2021-05-17T23:12:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
